diff --git a/CHANGELOG.md b/CHANGELOG.md index 27189afcd7..5bf39370df 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## [3.0.4+portage-3.0.12] - 2022-05-12 + +### Added + +- Updated the Term of Usage page and Privacy Policy information + ## [3.0.4+portage-3.0.11] - 2022-04-14 ### Fixed diff --git a/app/views/layouts/_footer.html.erb b/app/views/layouts/_footer.html.erb index be209de749..71944a40cd 100644 --- a/app/views/layouts/_footer.html.erb +++ b/app/views/layouts/_footer.html.erb @@ -68,8 +68,8 @@ }, Rails.configuration.branding[:organisation][:url])%>
<%= _("The information you provide will be used by the %{org_name} to offer you access to and personalisation of the %{application_name} service.") % - { application_name: ApplicationService.application_name, :org_name => Rails.configuration.x.organisation.names } %>
-<%= _("The %{org_name} processes the personal data of %{application_name} users in order to deliver and improve the %{application_name} service in a customised manner and to ensure each user receives relevant information.") % - { application_name: ApplicationService.application_name, :org_name => Rails.configuration.x.organisation.name } %>
-<%= _("The processing of your personal data by the %{org_name} is necessary for pursuing the following legitimate interests:") % - { :application_name => ApplicationService.application_name, :org_name => Rails.configuration.x.organisation.name } %>
+The following Privacy Policy applies to the DMP Assistant website (the Site), assistant.portagenetwork.ca / assistant.portagenetwork.ca/?locale=fr_CA, and the services available on or at the Site (taken together, the Service). The Service is supported by the Digital Research Alliance of Canada (the Alliance) and the University of Alberta Library (taken together, the Service Providers).
+The Alliance and the University of Alberta respect the privacy of individuals and will only collect, use, and disclose Personal Information in keeping with information access and privacy law.
+Administrator (Admin): A User of the Service with administrative permissions to edit basic organizational information, implement local customization and guidance, view usage statistics, and manage templates, plans, and users at their institution.
+Content : Data submitted to the Service by Users and Admin, including information entered as part of Plans, Templates, and Profiles (User and Organization).
+Data Management Plan (DMP; Plan): A formal document that details the strategies and tools to be implemented to effectively manage data both during a research project and after its completion. Users create Plans using the Service by choosing a DMP Template and answering questions, supported by Guidance and examples.
+DMP Assistant: DMP Assistant is a bilingual, web-based tool for preparing data management plans (DMPs). The tool follows international best practices in data stewardship and guides researchers step-by-step through key data management questions. DMP Assistant (the Service) is powered by an open source application called DMPonline, which is developed by the Digital Curation Centre (DCC) and shared under an AGPL license.
+DMP Template (Template): A series of key data management questions organized into sections and phases to be answered by the User in order to create a Plan.
+Personal Information (PI): Personal information is any recorded information that identifies an individual.
+Sensitive Data: Information that must be safeguarded against unwarranted access or disclosure, including but not limited to: Personal Information (PI); Personal Health Information (PHI); Educational records; Customer records; Criminal information; Geographic information (e.g., detailed locations of endangered species); Confidential personnel information; Information that is deemed confidential, information entrusted to a person, organization, or entity with the intent that it be kept private and access be controlled or restricted; Information that is protected by institutional policy from unauthorized access. Includes any information related to an identified or identifiable natural person, organization or entity.
+Service: The DMP Assistant website (the Site), assistant.portagenetwork.ca / assistant.portagenetwork.ca/?locale=fr_CA, and the services available on or at the Site (taken together, the Service), offered under partnership between the Digital Research Alliance of Canada (the Alliance) and host institution the University of Alberta Library (taken together, the Service Providers).
+Service Providers : The legal entities responsible for offering the Service, being the Digital Research Alliance of Canada (the Alliance) and the University of Alberta Library (taken together, the Service Providers).
+Service Support : Staff member(s) employed by the Service Providers to provide support for Service Users, answer User queries and work to resolve User issues.
+Site : DMP Assistant website (the Site), assistant.portagenetwork.ca / assistant.portagenetwork.ca/?locale=fr_CA.
+User : An individual who makes use of the Service by creating, sharing and downloading Plans, and otherwise adds Content. Users include Admin Users (see above definition for Administrator).
+In keeping with information access and privacy law, the Service Providers will only collect Personal Information for the purpose of providing the Service to Users.
+1.1 Users are required to create an account with DMP Assistant to make use of the Service. In order to create an account, the DMP Assistant collects Personal Information including name, an affiliated institution, and an email address.
+1.2 For security and version control purposes, DMP Assistant records the User's last login time, as well as information on when responses were saved and by whom. No other session information is stored nor is clickstream data tracked or retained in the DMP Assistant. The web hosting service (provided by University of Alberta) does collect clickstream data, but this information is captured anonymously and cannot be linked to a specific user (See the University of Alberta Privacy Policy). IP addresses and location data of Users of the system may be collected in order to provide the Service to Users. Opinions of Users are collected (via web-based feedback option) on a voluntary basis.
+1.3 For all visitors to the Site, administrative information is collected—such as pages viewed on the site, page access times, browser type, version and language, location, and operating system.
+In keeping with information access and privacy law, the Service Providers will only use Personal Information for the purpose of providing the Service to Users. The Service Providers process Personal Information in order to deliver and improve the Service in a customized manner and to ensure each User receives relevant information.
+2.1 Personal Information collected will be used for the following purposes:
<%= _("We will hold the personal data you provided us for as long as you continue using the %{application_name} service. Your personal data can be removed from this service upon request to the %{application_name} team within a period of 30 days.") % - { application_name: ApplicationService.application_name } %>
-<%= sanitize _("If you have any questions, please contact the %{application_name} team at: %{helpdesk_email}") % - { application_name: ApplicationService.application_name, :helpdesk_email => Rails.configuration.x.organisation.helpdesk_email } %>
-<%= _("This statement was last revised on %{revdate} and may be revised at any time with prior notice.") % - { :revdate => l(Date.new(2018, 5, 21), format: :readable) }%>
+2.2 For all visitors to the Site, administrative information collected will be used:
+2.3 Internally, only staff with a direct use for the data will have access to Personal Information collected.
+In keeping with information access and privacy law, the Service Providers will only disclose Personal Information as required by law, or with the express written consent of the individual whom the information is about.
+3.1 Personal Information collected via DMP Assistant account creation will be disclosed to the Service Providers for the purposes of this Service.
+3.2 Comments of Users, regarding Content, provided to Service Support will be shared with the Service Providers.
+3.3 The Service Providers will not sell, rent or trade Personal Information or mailing lists.
+3.4 The information may be transferred between the Service Providers' partner institutions but only for legitimate internal purposes.
+3.5 Administrative information and usage data will only be disclosed externally in a de-identifiable aggregate format.
+3.6 Disclosure of Personal Information contained in Content:
+3.6.1 In general, DMPs should not contain research data and/or sensitive information (such as personally identifiable information, detailed geographic data, or data otherwise subject to disclosure restrictions). In some cases, it may be reasonable or necessary to include information which could be considered sensitive (e.g. the name of a data source, such as a research hospital) in a DMP. Users are responsible for consulting with the appropriate regulators, guidance, policies and laws to ensure that their use of sensitive and/or identifiable information is appropriate and in accordance with relevant laws and regulations. Users should only include potentially sensitive information in DMPs if necessary. Users may consider creating public and private versions of their DMP in cases where a version of the DMP must be made public and sensitive information must be included in the DMP.
+3.6.2 It is the responsibility of Users to ensure that proper authority or consent has been obtained should submitted Consent include Personal Information or information which is otherwise sensitive. The Service Providers retain the right to request documentation concerning privacy, including research ethics approvals, Privacy Impact Assessments (PIA), or other documentation relating to regulation or approval of the disclosure of information in any instance where a privacy breach or violation of the Terms of Use is known or suspected. Users are responsible for complying with any obligations they may have through institutional affiliations or by law.
+3.6.3 The Service Providers will endeavour to honour the disclosure/non-disclosure requests of Users, subject to applicable laws including information and privacy law.
+The Service Providers will store Personal Information securely in keeping with accepted records management processes.
+4.1 Server storage of Personal information
+4.1.1 Personal Information collected by the Service Providers will be stored on secure servers located in Alberta, Canada.
+4.2 Personal Information collected or used will be held securely and confidentially by the Service Providers.
+4.3 Personal information collected or used will be held for as long as the User continues to use the Service.
+4.4 Personal Information collected will be administered under the records management protocol of the DMP Assistant.
+4.5 If it is discovered that Personal Information was received in error by the Service Providers, it will be securely destroyed after the User has been advised of the error.
+The Service Providers will ensure that appropriate security is applied to Personal Information collected, used, stored, or disclosed as part of this Service.
+The security of Personal Information will be administered in keeping with the DMP Assistant Information Security Policy.
+6.1 The Service Providers will maintain a Privacy Breach Protocol to address the management and mitigation of the breach.
+6.2 The Privacy Breach Protocol will be reviewed every two years, or as required.
+6.3 In the event of a privacy breach (unauthorized access to, or collection, use, or disclosure of Personal Information) authorized persons at Alliance and the University of Alberta will follow the Privacy Breach Protocol to assess and contain the breach about the relevant details and mitigation of the breach.
+6.4 Security breaches are addressed in the DMP Assistant Information Security Policy.
+6.5 As regards references to privacy breaches in the DMP Assistant Information Security Policy, these references will be in compliance with this Privacy Policy and with the Privacy Breach Protocol.
+6.6 Where reasonable, and in a timely manner, any persons impacted by a privacy breach will be advised by the Service Providers. Where large numbers of users may be impacted by a privacy breach, notification will be provided on the Site.
+7.1 By written request, individuals have the right to request access to Personal Information about themselves that is in the custody of, or under the control of, the Service Providers.
+7.2 Individuals may request, in writing, the correction of, or changes to, Personal Information about themselves that is in the custody of, or under the control of, the Service Providers.
+7.2.1 Should a requested correction or change not be made to the Personal Information, a copy of the request plus the reason for not granting the request will become part of the administrative record.
+7.3 Submitters may request, in writing, to have their Personal Information removed from the system administered by the Service Providers within a period of 30 days.
+7.3.1 Should the requested deletion of the Personal Information not be done, a copy of the request plus the reason for not granting the request will become part of the administrative record.
+7.4 Persons wishing to have Content containing Personal Information edited, amended, or removed from the Service should contact support@portagenetwork.ca.
+8.1 This Privacy Policy shall be posted on the DMP Assistant Site.
+8.2 This Privacy Policy shall be appended to the DMP Assistant Terms of Use Agreement.
+8.3 This Privacy Policy will be reviewed every two years, or as required.
+8.4 Notification of any changes to the collection, use, or disclosure of Personal Information, or changes to the Privacy Policy, will be posted on the DMP Assistant Site.
+Should you have any questions or concerns about the collection, use, or disclosure of Personal Information as regards the DMP Assistant, or about this Privacy Policy please contact us at support@portagenetwork.ca.
+The Service Providers reserve the right to suspend use by any party (User) if that party engages in, or is suspected of engaging in, activities that violate applicable information access and privacy laws.
The following document sets forth the Terms of Use for use of the DMP Assistant website (the Site), assistant.portagenetwork.ca / assistant.portagenetwork.ca/?locale=fr_CA, and the services available on or at the Site (taken together, the Service). The Service is offered by the Digital Research Alliance of Canada (the Alliance) and the University of Alberta Library (taken together, the Service Providers). The Service is offered subject to acceptance without modification of all of the terms and conditions contained herein (the Terms of Use) and all other operating rules, policies and procedures that may be published from time to time on the Site by the Service Providers. Use of the Service denotes agreement with the following terms.
+Administrator (Admin): A User of the Service with administrative permissions to edit basic organizational information, implement local customization and guidance, view usage statistics, and manage templates, plans, and users at their institution.
+Content : Data submitted to the Service by Users and Admin, including information entered as part of Plans, Templates, and Profiles (User and Organization).
+Data Management Plan (DMP; Plan): A formal document that details the strategies and tools to be implemented to effectively manage data both during a research project and after its completion. Users create Plans using the Service by choosing a DMP Template and answering questions, supported by Guidance and examples.
+DMP Assistant: DMP Assistant is a bilingual, web-based tool for preparing data management plans (DMPs). The tool follows international best practices in data stewardship and guides researchers step-by-step through key data management questions. DMP Assistant (the Service) is powered by an open source application called DMPonline, which is developed by the Digital Curation Centre (DCC) and shared under an AGPL license.
+DMP Template (Template): A series of key data management questions organized into sections and phases to be answered by the User in order to create a Plan.
+Personal Information (PI): Personal information is any recorded information that identifies an individual.
+Sensitive Data: Information that must be safeguarded against unwarranted access or disclosure, including but not limited to: Personal Information (PI); Personal Health Information (PHI); Educational records; Customer records; Criminal information; Geographic information (e.g., detailed locations of endangered species); Confidential personnel information; Information that is deemed confidential, information entrusted to a person, organization, or entity with the intent that it be kept private and access be controlled or restricted; Information that is protected by institutional policy from unauthorized access. Includes any information related to an identified or identifiable natural person, organization or entity.
+Service: The DMP Assistant website (the Site), assistant.portagenetwork.ca / assistant.portagenetwork.ca/?locale=fr_CA, and the services available on or at the Site (taken together, the Service), offered under partnership between the Digital Research Alliance of Canada (the Alliance) and host institution the University of Alberta Library (taken together, the Service Providers).
+Service Providers : The legal entities responsible for offering the Service, being the Digital Research Alliance of Canada (the Alliance) and the University of Alberta Library (taken together, the Service Providers).
+Service Support : Staff member(s) employed by the Service Providers who provide support for Service Users, answer User queries and work to resolve User issues.
+Site : DMP Assistant website (the Site), assistant.portagenetwork.ca / assistant.portagenetwork.ca/?locale=fr_CA.
+User : An individual who makes use of the Service by creating, sharing and downloading Plans, and otherwise adds Content. Users include Admin Users (see above definition for Administrator).
+Users of the Service agree to the following:
+The User hereby represents and warrants that they are lawfully entitled and have full authority to license the Service Providers to use the Content in the ways described in these Terms and Conditions; and are not under any obligation or restriction created by law, contract or otherwise that would prevent them from entering into and fully performing these Terms and Conditions.
+The Service Providers agree to:
+System Templates and associated guidance onthe Service (but not the Plans themselves) are under a Creative Commons Attribution 4.0 International (CC 4.0) license. Licenses are not automatically applied to Organizational Templates and their associated Guidance, and may be under their own license terms. Contact individual institutions for more details.
+Once Content has been submitted to the Service, Users may continue to edit, alter, augment, or remove any Content, with the exception of User accounts and Organization profiles.
+Anyone wishing to have Content removed from the Service, either for copyright infringement, or for other legitimate causes, should contact support@portagenetwork.ca.
+Anyone wishing to have Content containing Personal Information edited, amended, or removed from the Service should contact support@portagenetwork.ca.
+The Service Providers respect the privacy of Users and Content and will only collect, use, and disclose Personal Information in keeping with information access and privacy law. Further information about privacy protocols may be found in the DMP Assistant Privacy Policy.
+Users are responsible for the Content they submit to the Service. Users should consult the appropriate regulators, support staff, or individuals or departments responsible for policy or legal interpretation or compliance within their institutions to ensure that relevant legal, research ethics, privacy, research contract, intellectual property, or any other relevant considerations or obligations do not conflict with the Users proposed or intended use of the Service.
+Content added to the Service is only accessible to the User and those with whom the User chooses to share access. Plans are private by default. Administrators of the Service are only able to view select administrative details of a Plan, including:
+Administrators have no access to any other information in Users' Plans, unless:
+DMP Assistant keeps limited information about Users. In order to help identify and administer accounts, the Service Providers need to store profile information and email address. Personal Information collected by the Service Providers will be stored on secure servers located in Alberta, Canada.
+The Service Providers may use email addresses to contact Users to obtain feedback on use of the tool or to inform them of the latest developments or releases. The information may be transferred between the Portage partner institutions but only for legitimate internal purposes. The Service Providers will not sell, rent or trade any Personal Information provided.
+For security and version control purposes, DMP Assistant records the User's last login time, as well as information on when responses were saved and by whom. No other session information is stored nor is clickstream data tracked or retained in the DMP Assistant. The web hosting service (provided by University of Alberta) does collect clickstream data, but this information is captured anonymously and cannot be linked to a specific user. See the University of Alberta Privacy Policy.
+In the event of a privacy breach, (unauthorized access to or collection, use, or disclosure of Personal Information) authorized persons at Alliance and the University of Alberta will follow a Privacy Breach Protocol to assess and contain the breach about the relevant details and mitigation of the breach.
+The Alberta Freedom of Information and Protection of Privacy Act (" FOIP") generally applies to any records that are collected, used or disclosed in the course of the operations of the university (subject to some limited exceptions). FOIP imposes obligations on the university to:
+Passwords of registered users are stored in encrypted form and cannot be retrieved. Forgotten passwords must be reset. Passwords are not stored for users registering and logging in using CAF Authentication.
+This website uses Google Analytics to capture and analyze usage statistics, but it doesn't link to specific users, and information remains anonymous. Users may choose to opt-out of having website activity tracked by Google Analytics. To do so, visit the Google Analytics opt-out page and install the add-on for your browser.
+The DMP Assistant does not currently use third-party APIs. Cookies are small pieces of text sent to your web browser by a website you visit. They are stored in your web browser and allow the website to improve your user experience. Cookies cannot be used to identify you personally. DMP Assistant uses session cookies to keep the session information so that the User's interaction with the application is persistent on their visit. The cookie will be automatically created when the User starts browsing the site and will be expired when the browsing session ends. DMP Assistant also uses cookies for analytics purposes with Google Analytics. A set of cookies may be used to collect and report website usage statistics without personally identifying individual visitors, so we can understand how visitors are engaged with the application.
+The Service Providers reserve the right to suspend use by any party (User) if that party engages in, or is suspected of engaging in, activities that violate applicable copyright or privacy laws, or in any other way breaches these Terms of Use.
+The Content in the Service is made available to Users on an "AS IS" basis. Except as set forth herein, and to the maximum extent permitted by law, the Service Providers make no representations or warranties, express or implied, including, without limitation, (i) implied warranties of accuracy, quality, performance, compatibility, merchantability and/or fitness for a particular purpose, (ii) that any such Content or other material is free from personally identifiable, sensitive, infringing or illegal data or material, and (iii) that any such Content not suffer loss, corruption or destruction. While the Service Providers will try to ensure that the Service, the Site and its software, are safe from bugs, viruses, disruptions and delays, we do not represent or warrant that they will always be so.
+In agreeing to these Terms of Use, you indemnify and hold the Service Providers harmless from and against any and all loss, cost, expense, liability, or damage, including, without limitation, all reasonable attorneys' fees and court costs, arising from the i) use or misuse of the Service; (ii) your access to the Site, use of the Services, violation of the Terms of Use by you; or, (iii) the infringement by you, or any third party using your account, of any intellectual property or other right of any person or entity. Such losses, costs, expenses, damages, or liabilities shall include, without limitation, all actual, general, special, and consequential damages.
+A printed version of the Terms of Use and of any notice given in electronic form shall be admissible in judicial or administrative proceedings based upon or relating to the Terms of Use to the same extent and subject to the same conditions as other business documents and records originally generated and maintained in printed form. You and the Service Providers agree that any cause of action arising out of or related to the Service must commence within one (1) year after the cause of action arose; otherwise, such cause of action is permanently barred.
+These Terms and Conditions shall be governed by and interpreted in accordance with the applicable provincial and/or federal laws of Canada. All disputes under these Terms and Conditions will be resolved in the applicable provincial or federal courts of Canada. You consent to the jurisdiction of such courts and waive any jurisdictional or venue defenses otherwise available. Use of the Service is not authorized in any jurisdiction that does not give effect to all provisions of the Terms of Use, including without limitation, this section.
+The Terms of Use are the entire agreement between you and the Service Providers with respect to the Service and use of this Site, and supersede all prior or contemporaneous communications and proposals (whether oral, written or electronic) between you and the Service Providers with respect to this Site (but excluding the use of any software which may be subject to a separate end-user license agreement). If any provision of the Terms of Use is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary so that the Terms of Use will otherwise remain in full force and effect and enforceable.
+The Service Providers reserve the right, at their sole discretion, to modify or replace any of the Terms of Use at any time.
+Any changes to the collection, use, or disclosure of Personal Information, or changes to the Privacy Policy, will be posted on the DMP Assistant website.
+It is the User's responsibility to check the Terms of Use periodically for changes. The User's continued use of the Service following the posting of any changes to the Terms of Use constitutes acceptance of those changes.
+If you have any questions or comments with respect to the Service, or if you are unsure whether your intended use is in line with these Terms of Use, or if you seek permission for a use that does not fall within these Terms of Use, please contact support@portagenetwork.ca.
+If you have any questions or concerns about the collection, use, or disclosure of Personal Information as regards DMP Assistant, please view the Privacy Policy or contact us at support@portagenetwork.ca.
+You acknowledge that the copyright in any additional data added by the Service Providers to the user materials, and any search software, user guides, documentation and any other intellectual property that is prepared by the Service Providers to assist Users in using the Service, including the submission of Content, will belong to the Service Providers.
+This Terms of Use document is available under a Creative Commons Attribution-ShareAlike 4.0 (CC BY-SA 4.0) License.
+ +